adobeflashplayer12.0.exe

QUANTO SOLUCOES E SISTEMA LTDA

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘AdobeFlashPlayer12.0.exe’.
Publisher:
QUANTO SOLUCOES E SISTEMA LTDA  (signed and verified)

MD5:
a5e36205e7bcc9cd82e63ea2f92336d9

SHA-1:
64b9eb2dbbf71ca38bdcf3258453715f915a342c

SHA-256:
7420385e9989a2d0359bde2b7c1bef47eca5f078639a2b9dabcc49b720c75553

Scanner detections:
13 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/26/2024 2:24:56 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.371129
987

AhnLab V3 Security
Trojan/Win32.Genome
14.05.24

AVG
Lebros
2015.0.3465

Bitdefender
Gen:Variant.Kazy.371129
1.0.20.720

Emsisoft Anti-Malware
Gen:Variant.Kazy.371129
8.14.05.24.08

F-Secure
Gen:Variant.Kazy.371129
11.2014-24-05_7

G Data
Gen:Variant.Kazy.371129
14.5.24

McAfee
Artemis!A5E36205E7BC
5600.7121

MicroWorld eScan
Gen:Variant.Kazy.371129
15.0.0.432

Qihoo 360 Security
Malware.QVM18.Gen
1.0.0.1015

Trend Micro House Call
PAK_Generic.009
7.2.144

Trend Micro
PAK_Generic.009
10.465.24

VIPRE Antivirus
Trojan.Win32.Packer.EnigmaProtector1.1X-1.3X
28664

File size:
2.2 MB (2,296,160 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\adobeflashplayer12.0.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/2/2014 9:00:00 PM

Valid to:
4/3/2015 8:59:59 PM

Subject:
CN=QUANTO SOLUCOES E SISTEMA LTDA, O=QUANTO SOLUCOES E SISTEMA LTDA, L=PRESIDENTE PRUDENTE, S=SAO PAULO, C=BR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
00B87EDE3281FFB1EE77DF86B54A8CB0

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:6yAlTYlo7QnW+Vkc55nNiXnHxXEaUWQDkoFRvjM2sL:SlkY2kc55mnHxXALhFRvV+

Entry address:
0x412E6

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 10, 40, 00, E8, 01, 00, 00, 00, 9A, 83, C4, 10, 8B, E5, 5D, E9, B6, 7A, 89, 00, 38, 59, 0B, 54, 52, A0, 00, E4, 9F, 75, 17, 38, AE, 5D, 8E, A1, 86, 84, F9, 8F, 63, 9B, B2, 07, 0D, F9, 6F, B2, 94, A0, 93, 3D, 66, B9, 7B, 2E, D5, 77, EF, B0, 7D, ED, 23, 8E, A7, DA, 16, AC, 1D, 70, 4D, 9F, 10, 46, 72, C8, CA, 0C, 4A, F4, CA, A5, 85, AF, 04, 07, C0, 0A, 1A, 22, FD, E0, BB, 7F, 78, EA, 31, 6F, 2F, CE, B3, 00, 4F, 66, 08, B3, B0, A5, E7, 79, 75, BF, 85, 0E, 99, 65, 1E, 6A, 6E, 76...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
599 KB (613,376 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
AdobeFlashPlayer12.0.exe

Command:
C:\users\{user}\appdata\roaming\adobeflashplayer12.0.exe


Scan adobeflashplayer12.0.exe - Powered by Reason Core Security